首页 | 本学科首页   官方微博 | 高级检索  
     

一个前向安全无证书代理签名方案的安全性分析*
引用本文:胡国政,韩兰胜,夏祥胜,王展青. 一个前向安全无证书代理签名方案的安全性分析*[J]. 计算机应用研究, 2011, 28(6): 2191-2192. DOI: 10.3969/j.issn.1001-3695.2011.06.052
作者姓名:胡国政  韩兰胜  夏祥胜  王展青
作者单位:1. 武汉理工大学,理学院,武汉,430070
2. 华中科技大学,计算机学院,武汉,430074
基金项目:国家自然科学基金资助项目
摘    要:对一个前向安全无证书代理签名方案进行分析,指出这个方案既不具有不可伪造性,也不具有前向安全性。证明了该方案对于公钥替换攻击是不安全的,即敌手通过替换原始签名者和代理签名者的公钥可以伪造该代理签名者对任意消息的代理签名,给出了伪造攻击方法。指出该方案不具备前向安全性的原因,即该签名方案的代理密钥更新算法没有利用时段标识,代理签名没有明确包含时段信息。

关 键 词:无证书签名;代理签名;前向安全;公钥替换攻击;双线性对
收稿时间:2010-11-08
修稿时间:2011-05-16

Security analysis of forward secure certificateless proxy signature scheme
HU Guo-zheng,HAN Lan-sheng,XIA Xiang-sheng,WANG Zhan-qing. Security analysis of forward secure certificateless proxy signature scheme[J]. Application Research of Computers, 2011, 28(6): 2191-2192. DOI: 10.3969/j.issn.1001-3695.2011.06.052
Authors:HU Guo-zheng  HAN Lan-sheng  XIA Xiang-sheng  WANG Zhan-qing
Affiliation:(1. School of Science, Wuhan University of Technology,Wuhan,43007, China;2. School of Computer, Huazhong University of Science & Technology,Wuhan 430074, China;3.Dept. of Computer, Wuhan Polytechnic University,Wuhan 430070,China)
Abstract:A forward secure certificateless proxy signature scheme was analyzed, and it was pointed out that the scheme is neither unforgeable nor forward secure. It was showed that the scheme is insecure under the public key replacement attack. The adversary can forge a proxy signature for any message of any proxy signer by substituting the public keys of the original signer and the proxy signer. The attack method is given in detail. The reason without the forward secure property is that the updating algorithm of proxy private keys of the scheme does not use time periods and the proxy signatures do not explicitly include period identities. So the scheme is not a forward secure signature scheme.
Keywords:certificateless signature   proxy signature   forward security   public key replacement attack   bilinear pairing
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《计算机应用研究》浏览原始摘要信息
点击此处可从《计算机应用研究》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号